Vulnerability Bulletins |
[20171101] - Core - LDAP Information Disclosure |
|
| Affected software | Joomla |
|
Project: Joomla! SubProject: CMS Severity: Medium Versions: 1.5.0 through 3.8.1 Exploit type: Information Disclosure Reported Date: 2017-October-06 Fixed Date: 2017-November-07 CVE Number: CVE-2017-14596 Description Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password. Affected Installs Joomla! CMS versions 1.5.0 through 3.8.1 Solution Upgrade to version 3.8.2 Contact The JSST at the Joomla! Security Centre. Reported By: Dr. Johannes Dahse, More info: http://feeds.joomla.org/~r/JoomlaSecurityNews/~3/_Ud0fZdMIyg/714-20171101-core-ldap-information-disclosure.html |
|






